Junglewise Threat Intelligence

CVE-2026-43510: CISA manage.get.gov Incorrect Privilege Assignment in Portfolio Management

CVE-2026-43510 · Severity: medium · CVSS 5.9 · Published 2026-05-07

Executive brief

The .gov domain registrar, managed by CISA, contained a security flaw that could allow an organization administrator to gain control over domains belonging to a different organization. By exploiting a lack of validation in the domain assignment process, an administrator could grant themselves or others management privileges for domains they do not own. This could lead to unauthorized changes to government domain settings and a breach of isolation between different government agencies.

Technical details

A privilege escalation vulnerability exists in the manage.get.gov registrar platform due to missing portfolio validation in the domain assignment logic. Specifically, the '_process_added_domains' method in 'registrar/views/portfolios.py' retrieves domains by ID without verifying that the domain's 'portfolio_id' matches the administrator's portfolio. An authenticated portfolio administrator can exploit this by submitting domain IDs belonging to other organizations, effectively granting 'Domain Manager' roles to users across portfolio boundaries. This breaks the intended isolation between different government entities. The issue was resolved in version 1.176.0 by implementing explicit ownership checks during the assignment process.

Affected products

  • CISA manage.get.gov 1.92.0 to 1.175.0

Timeline

  • 2026-03-31: other: Issue first identified internally
  • 2026-04-24: patched: Fix merged into main branch
  • 2026-04-30: patched: Version 1.176.0 released
  • 2026-05-07: disclosed: Security advisory published

References